CosmosEscape: The Exploit Chain That Exposed the Azure Cosmos DB Master Key
Wiz researchers exposed the Azure Cosmos DB Master Key via the CosmosEscape exploit chain. Microsoft patched the critical flaw risking Teams and Copilot data.
Illustrative image generated with AI
From Owning a Gremlin Database to Code Execution on the Gateway
Wiz reconstructed an exploit chain (dubbed CosmosEscape) that starts from a seemingly innocuous premise: control of a Gremlin database in Azure Cosmos DB. The researchers demonstrated how it was possible to exploit a vulnerable entry point to execute arbitrary code directly on the multi-tenant gateway that routes queries to the Service Fabric clusters. Once execution was achieved, the malicious code could access two internal assets: the Cosmos Master Key, a global signing key, and the regional Config Store, which contains metadata for all accounts.
The Key That Opened Every Door: Total Access to Any Tenant’s Data
The Cosmos Master Key was the most critical element of the entire infrastructure. With that key, Wiz explains, it was possible to sign valid requests to retrieve the primary keys of any Cosmos DB account, regardless of the API used — SQL, MongoDB, Cassandra, or Gremlin — tenant, or region. Network isolation became irrelevant. The compromised gateway operated within Microsoft’s cloud, bypassing any restrictions configured by customers. Read access to the Config Store also allowed identifying specific organizations and obtaining their primary keys. Writing to the same store, though not demonstrated on real customers, could have altered the network settings of accounts.
Microsoft’s Response: 48 Hours to Patch the Breach, Eight Months to Remove the Key
Wiz’s report dates back to November 2025. In less than two days, Microsoft disabled the Gremlin entry point that made the attack possible, breaking the first link in the chain. The permanent fix, however, required a deeper intervention: the complete removal of the key at the platform level. This was rolled out gradually across all regions and completed just in these weeks of July 2026. Microsoft’s internal investigation did not detect any malicious activity outside of the researchers’ tests. No unauthorized access to customer data, nor signs of active exploitation.
Side Effects: From Teams to Copilot, Services at Risk
Even without proof of real compromises, the potential impact of CosmosEscape was vast. Several high-profile Microsoft services store data on Cosmos DB: among them Teams and Copilot. An attacker in possession of the Master Key could have read and modified data from conversations, meetings, AI assistant interactions, as well as databases of any organization. The absence of CVE identifiers does not lessen the severity. Wiz considers the vulnerability critical, and will present it in detail at Black Hat USA in Las Vegas on August 6.
What to Do Now: No Action Required, But Don’t Lower Your Guard
Since the fix is service-side, Microsoft does not require any action from Azure tenant administrators. The protection is already active. However, continuous monitoring of the cloud environment remains essential: verifying Cosmos DB access logs, keeping SDKs and client libraries up to date, and following the security best practices recommended by Azure. The CosmosEscape affair confirms that even managed services can hide unexpected flaws. The transparency of researchers remains an essential defense.
Sources
This article is an original reworking based on the sources below.




